Skip Navigation
LineageOS is currently installed on 1.5 million Android devices
  • Where are these OEMs that allow proper bootloader unlocking on most of their range?

    Google, Sony ...? Huawei stopped doing it, Oppo & Samsung doesn't last I checked.

  • Does running applications inside a container as an unprivileged user have any security benefits?
  • It means that if someone breaks out of your container, they can only do things that user can do.

    Can that user access your private documents (are these documents in a container that also runs under that user)?

    Can that user sudo?

    Can that user access SSH keys and jump to other computers?

    Generally speaking, the answer to all of these should be "no", meaning that each group of containers (or risk levels etc) get their own account.

  • Apple's called Android a "massive tracking device" in an internal presentation
  • (If you buy a suitable device) You don't have to use the preloaded OS (see Graphrne, Lineage etc).

  • recommends for Headless windows install and configuration?
  • Not quite, I have to go through out of box, and then join it to the domain, but then yes!

    Applies security policy, install apps, disables bloat, login in with central username and pass, get mapped drives etc

  • recommends for Headless windows install and configuration?
  • I have a Windows AD domain and have my preferences and some apps as GPOs.

    In the server world we use Ansible, or in some cases maybe PowerShell DSC.

    Ansible is much more focused on Linux and orchestration, but does have some support for Windows, and DSC is for Windows Servers.

    Both use YAML or similar structured config to impart a state, e.g.

    - name: Install Firefox
      Ansible.builtin.package:
        name: firefox
        state: present
    

    Meaning that ansible does the legwork to make sure FF is installed.

  • Google Disabling Phone 2 Factor?
  • No, this is

    • buying a surface from Microsoft
    • immediately wiping it and installing Linux
    • Microsoft then forcing you to authenticate using the device that is only tied to your account via purchase, and NOT login records, AND disabling other forms of auth
  • Deleted
    *Permanently Deleted*
  • gedit in native Linux or WSL2. use it for Ansibke, python, C, bash, basically anything I need to edit. Has a git plugin, bottom terminal pane, left open files / current folder pane. Does all I need it to do, and it's not a huge fuckoff electron app.

  • Apple iPhone 15 relegated to USB 2.0 unless you buy the Pro
  • I'm pretty certain that the USB IF decided to use the max possible Gbps as the cable rating, rather than the mess that was

    USB 3.0 USB 3.1 USB 3.1 (Gen 1) USB 3.1 (Gen 2) ...

    So it's more likely apple are just being specific in the type of cable you need.

  • FOSS version of google docs to run on a home server?
  • There is a db migration command that I used to do the same thing, was pretty painless, just needed to run that and then update the config iirc

  • Russian airliner forced to land in open field
  • Landing gears are usually designed to drop by gravity (or manual hand cranking) alone if there's a hydraulic failure.

  • SanDisk Extreme SSDs are “worthless,” multiple lawsuits against WD say
  • Just a point of clarification: Don't use RAID 5 for more than 2-4 TB. The rebuild takes so long that the mean-time-between read errors statistic basically guarantees a read error while rebuilding, which may cause the controller to trash the array.

    That and rebuilding that much data might push one of the drives over the edge anyway.

  • Is Google going to make Android a nightmare?
  • The linked article — and others — explain that in Android 10+, (a) executable binaries can no longer reside in a read/write directory, and (b) access to /sdcard will go away. Simply put, these changes destroy my application's ability to function, and that of Termux as well.

    That sounds like proper security to me? Inability to access the user's storage is a bit lame, but they've been moving to nicer APIs for that anyway.

    Android is a mobile phone OS, not desktop / embedded Linux.

  • What exactly does systemd do?
  • One thing that people miss - either out of ignorance, or because it goes against the narrative - is that systemd is modular.

    One part handles init and services (and related things like mounts and sockets, because it makes sense to do that), one handles user sessions (logind), one handles logging (journald), one handles networking (networkd) etc etc.

    You don't have to use networkd, or their efi bootloader, or their kernel install tool, or the other hostname/name resolution/userdb/tmpfiles etc etc tools.

  • The WHO is about to declare aspartame can cause cancer
  • I'm going to agree with Burstar here - if you're setting out to prove that something is possible, you're going to give it the best chance you can. Once you know its possible (whether its something like using an arduino to simulate an old price of hardware, or if a compound can cause cancer), you go and refine it down.

  • Firefox 115 released
  • So allowing any random, possibly compromised, possibly installed by malware, add-on to run during the Firefox account login pages (see the list of URLs in this thread) isn't a security concern to you?

  • NRoach44 NRoach44 @lemmy.ml
    Posts 0
    Comments 15